Broken trust: Lessons from Sunburst
Mon, Mar 29, 2021

Report by Trey Herr, Will Loomis, Emma Schroeder, Stewart Scott, Simon Handler, 
and Tianjiu Zuo

Related Experts: Trey Herr, Will Loomis, Emma Schroeder, Stewart Scott, Simon 
Handler

Table of contents


Executive summary
Introduction
I—Sunburst explained
II—The historical roots of Sunburst
CCleaner
Kingslayer
Flame
Able Desktop
WIZVERA VeraPort
Operation SignSight
Juniper
Trendlines leading to Sunburst
III—Contributing factors to Sunburst
Deficiencies in risk management
Hard-to-defend linchpin cloud technologies
Brittleness in federal cyber risk management
IV—Toward a more competitive cybersecurity strategy
Seeking flow
Build better on what works (or could)

Ruthlessly prioritize risk
Improve the defensibility of linchpin software
Enhance the adaptability of federal cyber risk management


https://www.atlanticcouncil.org/in-depth-research-reports/report/broken-trust-lessons-from-sunburst/#executivesummary

-- 
Iw mailing list
[email protected]
http://sticklist.org/mailman/listinfo/iw_sticklist.org

Reply via email to